Description
Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.
Published: 2026-09-02
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution (inferred)
Action: Assess Impact
AI Analysis

Impact

The vulnerability exists in all versions of the Drupal Gammu SMS Daemon, as indicated by the wildcard version range. No explicit weakness or detailed impact is disclosed in the advisory. The weakness is a buffer overflow (CWE-119). Based on the product type—a network-accessible messaging daemon—and the severity designation of critical, it is reasonable to infer that a successful exploitation could allow an attacker to execute arbitrary code or commands on the host system. In the absence of vendor-provided details, the exact consequences for confidentiality, integrity, and availability remain unspecified, but the critical rating implies potential severe damage.

Affected Systems

All installations of the Drupal Gammu SMS Daemon, regardless of version, are affected. The vulnerability encompasses every release reflected by the *.* notation in the advisory.

Risk and Exploitability

The Exploit Prediction Scoring System score is not available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The advisory does not describe a confirmed public exploit, attack vector, or required privilege level. As a result, while the potential impact is high, the likelihood of exploitation in the wild is uncertain and may be reflected by the lack of documented exploitation activity. Defenses should treat this as a medium severity issue (CVSS 5.9) that warrants prompt attention, even in the absence of confirmed exploits.

Generated by OpenCVE AI on September 3, 2026 at 14:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the Drupal security advisory page linked in the advisory for an available patch or newer release that addresses the Gammu SMS Daemon issue.
  • If a patch is available, upgrade the Gammu SMS Daemon to the fixed version immediately.
  • If no patch exists at the time of assessment, stop or uninstall the Gammu SMS Daemon service to eliminate the exposed attack surface.

Generated by OpenCVE AI on September 3, 2026 at 14:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
References

Thu, 03 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94

Thu, 03 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N'}


Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal gammu Sms Daemon
Vendors & Products Drupal
Drupal gammu Sms Daemon

Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94

Wed, 02 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.
Title Gammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100
References

Subscriptions

Drupal Gammu Sms Daemon
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-09-19T14:58:44.456Z

Reserved: 2026-08-19T16:36:05.908Z

Link: CVE-2026-76755

cve-icon Vulnrichment

Updated: 2026-09-02T18:42:41.537Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-02T13:18:10.780

Modified: 2026-09-19T15:17:01.690

Link: CVE-2026-76755

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T14:15:06Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer